PatchSiren cyber security CVE debrief
CVE-2026-54192 Ays Pro CVE debrief
CVE-2026-54192 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Popup box plugin versions <= 6.2.9. The vulnerability has a CVSS score of 7.1 and was published on 2026-06-17. The vulnerability allows an unauthenticated attacker to perform XSS attacks. Users of the affected plugin should take immediate action to mitigate the risk. The CVE record and NVD detail provide further information on the vulnerability. Patchstack has provided a mitigation reference for the vulnerability.
- Vendor
- Ays Pro
- Product
- Popup box
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of the Popup box plugin versions <= 6.2.9 should be aware of this vulnerability and take necessary actions to mitigate the risk. Web application security teams and cybersecurity professionals should also be aware of this vulnerability and monitor for potential attacks.
Technical summary
CVE-2026-54192 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Popup box plugin versions <= 6.2.9. The vulnerability has a CVSS score of 7.1 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L. The weakness is classified as CWE-79. The vulnerability allows an unauthenticated attacker to perform XSS attacks.
Defensive priority
high
Recommended defensive actions
- Update the Popup box plugin to a version greater than 6.2.9
- Implement additional security measures to detect and prevent XSS attacks
- Monitor web application logs for potential attacks
- Use a web application firewall to detect and prevent attacks
- Perform regular security audits and vulnerability assessments
- Educate users on the risks of XSS attacks and how to prevent them
Evidence notes
The vulnerability was reported by Patchstack and is classified as a high-severity vulnerability. The CVE record and NVD detail provide further information on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54192 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54192
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54192 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54192
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.